Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25684
HistoryJun 15, 2020 - 7:39 a.m.

Privilege Escalation

2020-06-1507:39:58
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19

EPSS

0.001

Percentile

30.8%

Apache Karaf is vulnerable to privilege escalation. A user with a viewer role and non-admin privilege can call get* in etc/jmx.acl.cfg. Subsequently, calling getMBeansFromURL can lead to SSRF and pollution of the MBean registry.

EPSS

0.001

Percentile

30.8%